Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85454 MEDIUM 6.1 2026-09-03 MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stac…
CVE-2026-85453 MEDIUM 6.1 2026-09-03 MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set…
CVE-2026-85452 HIGH 8.8 2026-09-03 MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-by…
CVE-2026-85451 HIGH 7.1 2026-09-03 MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command a…
CVE-2026-85450 HIGH 7.5 2026-09-03 MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers …
CVE-2026-85449 HIGH 7.5 2026-09-03 MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbo…
CVE-2026-85448 HIGH 7.5 2026-09-03 MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publi…
CVE-2026-85447 HIGH 7.5 2026-09-03 MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived …
CVE-2026-85446 HIGH 7.5 2026-09-03 MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs di…
CVE-2026-85445 HIGH 7.5 2026-09-03 MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without vali…
CVE-2026-85444 HIGH 7.5 2026-09-03 MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original …
CVE-2026-85443 HIGH 7.5 2026-09-03 MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout…
CVE-2026-85442 HIGH 7.5 2026-09-03 MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer…
CVE-2026-85441 HIGH 7.5 2026-09-03 MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted messag…
CVE-2026-85440 CRITICAL 9.8 2026-09-03 MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data …
CVE-2026-85439 HIGH 7.8 2026-09-03 MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metachara…
CVE-2026-85438 CRITICAL 9.8 2026-09-03 MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used a…
CVE-2026-85437 CRITICAL 9.8 2026-09-03 MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. A…
CVE-2026-85436 HIGH 7.5 2026-09-03 MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to corrupt heap memory by sendi…
CVE-2026-85435 CRITICAL 9.1 2026-09-03 MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shor…
CVE-2026-85434 CRITICAL 9.1 2026-09-03 MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with …
CVE-2026-85433 CRITICAL 9.8 2026-09-03 MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. At…
CVE-2026-85432 HIGH 8.2 2026-09-03 MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by suppl…
CVE-2026-85431 HIGH 7.5 2026-09-03 MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send …
CVE-2026-85430 CRITICAL 9.1 2026-09-03 MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attack…